
Apple alerts users in 110 countries about mercenary spyware attacks
Apple confirmed sending new threat notifications on August 13 to users in 110 countries, warning of highly targeted mercenary spyware attacks. Recipients are urged to take the alerts seriously and enable Lockdown Mode.
Apple has confirmed that on August 13, 2026, it sent a new batch of threat notifications to iPhone users in 110 countries, warning them that they may have been individually targeted by mercenary spyware. The alerts, which the company calls "Apple Threat Notifications," are not a new feature; Apple has been sending them multiple times a year since 2021. The company does not identify the specific spyware behind each alert, but it describes the attacks as highly targeted, expensive, and often short-lived, which makes them difficult to detect and prevent.
Mercenary spyware is commercially developed surveillance software sold to governments or other clients for targeted attacks on specific individuals. Apple cites NSO Group's Pegasus as an example of this type of spyware, and forensic investigations into previous Apple threat notifications have confirmed Pegasus infections in some cases. However, Apple does not attribute individual alerts to any government, company, or geographical region. The list of potential targets includes journalists, activists, politicians, and diplomats, who have historically been singled out by such spyware. According to Apple, these attacks cost millions of dollars and are used against a very small number of people, meaning the vast majority of users will never be targeted.
Apple relies on its own threat intelligence and investigations to send these alerts. The company describes them as "high-confidence alerts" that a user has been individually targeted, even though its investigations cannot achieve absolute certainty. Apple cannot provide details about what triggers a notification because that could help attackers adapt and evade future detection. When Apple detects this activity, it sends an email and an iMessage notification to the email addresses and phone numbers associated with the user's Apple Account. The email usually comes from threat-notifications@email.apple.com, and Apple warns that fake versions of these alerts exist, so recipients should verify any notification carefully.
To verify that a threat notification is genuine, users should log in to account.apple.com; if Apple sent the alert, it will appear at the top of the page after signing in. Apple's legitimate threat notification emails will never ask users to click a link, open a file, install an app or profile, or provide an Apple Account password or verification code. Apple has also updated the threat notification experience to make it easier for recipients to find important information and follow recommended steps to protect their accounts and devices. If you receive one of these alerts, Apple recommends taking it seriously and following the guidance.
The recommended steps for anyone affected include enabling Lockdown Mode, which is a security setting that limits certain iPhone features to reduce the risk of spyware, keeping devices updated with the latest software, and reaching out to a cybersecurity expert. For website owners and IT teams who manage devices for employees, a secure DNS service like AEU DNS can add an extra layer of protection by blocking connections to known malicious domains that spyware might use. While most readers will never receive such a notification, understanding the threat and practicing good security hygiene is essential for everyone who uses connected devices.
How to Protect Yourself
- If you get an Apple threat notification, go to account.apple.com and log in to check if the alert is real before you do anything else.
- Never click links, open files, or install anything from an email that claims to be an Apple threat notification; real ones do not ask you to do that.
- Turn on Lockdown Mode on your iPhone by going to Settings > Privacy & Security > Lockdown Mode if you are at higher risk.
- Keep your iPhone and any other devices updated to the latest software version to close known security holes.
- If you think you have been targeted, contact a cybersecurity expert or Apple Support for help.